Guide
Significant Data Fiduciary under the DPDP Act: who qualifies and what changes (Section 10)
How the government designates a Significant Data Fiduciary, the extra Section 10 duties (India-based DPO, independent auditor, DPIAs) and how to prepare if you might qualify.
Most organisations under the DPDP Act are ordinary Data Fiduciaries. A smaller group carries a heavier set of duties: Significant Data Fiduciaries (SDFs). If you might be one, the extra obligations change your compliance plan materially, so it is worth knowing early.
Who becomes an SDF
The Central Government notifies a Data Fiduciary, or a class of them, as significant based on factors set out in Section 10: the volume and sensitivity of personal data processed, the risk to Data Principals, potential effects on the sovereignty and integrity of India, risks to electoral democracy, and security of the state. There is no single number, it is a risk-and-impact judgement the government makes.
What changes if you are one
- Appoint a Data Protection Officer based in India, reporting to the board or governing body.
- Appoint an independent Data Auditor to evaluate compliance.
- Carry out periodic Data Protection Impact Assessments and audits.
- Observe any additional measures the government prescribes for SDFs.
What to do if you might qualify
If your data volume is large or you handle sensitive categories, plan as if you may be notified: the DPO and audit functions take time to stand up. The readiness assessment flags the SDF track when your answers suggest it, and a DPO or consultant can help you build the governance layer.
Frequently asked questions
Who decides if I am a Significant Data Fiduciary?
What extra duties does an SDF have?
Is there a fixed data-volume threshold?
Guidance, not legal advice. dpdpactindia.in is an independent resource, not affiliated with the Government of India. Confirm specifics against the enacted Act and Rules.